Know which penetration testing leads deserve a scoping call
Ask prospects what environment needs testing, whether they hold documented authorization, and how many systems are in scope — then require an authorization document before a scoping call ever gets booked.
The exact intake your penetration testing leads complete
This is the real 6-question guided intake for Penetration Testing — the same flow your customers finish before you ever pick up the phone.
What a qualified penetration testing lead should tell you
Authorized, simulated attacks against a defined set of systems, applications, or networks to surface exploitable weaknesses, scoped by asset type, count, and proof of ownership before any testing begins.
- Environment Testing
- Own Or Have Documented
- Prompting This Testing
- How Many Systems, Applications,
- This Environment Ever Undergone
- Testing Take Place
The questions your team needs answered
Every penetration testing intake asks these — and why each one matters.
| Question | Why it matters |
|---|---|
| What type of environment needs testing? | The environment type determines which specialists and test methodology to scope, since every listed option except a nonsensical case carries high qualification weight. |
| Do you own or have documented authorization to test these systems? | Documented authorization scores 10 versus just 1 for a 'no' answer, because testing without proof of ownership is a legal risk your team can't take on. |
| What is prompting this testing need? | The stated driver — compliance, incident, routine, launch, or partner request — shapes how urgently and how the scoping call should be framed. |
| Approximately how many systems, applications, or endpoints are in scope? | The number of in-scope systems or endpoints signals the likely size and cost of the engagement before your team gets on a call. |
| Has this environment ever undergone a penetration test before? | Knowing whether the environment has been tested before tells your team if they're starting a baseline assessment or building on prior findings. |
| When do you need testing to take place? | Stated timeline separates leads ready to schedule immediately from those still just exploring providers. |
How Cliont scores penetration testing leads
Every answer is weighted automatically — no manual review required.
Value signals
- Web application
- Mobile application
- Network infrastructure
- Cloud environment
- Internal systems
- Not sure
Urgency signals
- Immediately
See the lead your team receives
Penetration Testing Lead
From first click to qualified lead
Follow prospects and clients through one smooth, guided flow.
They land & meet you
Your video greeting plays instantly — a real face instead of a blank form.
They explain the project
Smart questions adapt to their project and capture the full scope.
They share the details
The scope and any documents come attached, so you can scope before the first call.
You get a ready lead
Scored and qualified — waiting for you to win it.
Built for penetration testing workflows
| Cliont capability | Penetration Testing application |
|---|---|
| Conditional document upload | Requires proof of system ownership or a signed authorization letter before a lead is marked qualified, closing the risk exposed by a 'No' answer on the authorization question. |
| Weighted scoring engine | Applies the catalog's 10-vs-1 weighting on documented authorization so an unauthorized request never outranks a properly cleared one, regardless of how valuable the target environment looks. |
| Answer-based routing | Directs prospects describing scanning-only needs toward the Vulnerability Assessment intake instead, based on their stated environment and driver. |
| CRM handoff with structured fields | Passes environment type, scope size, and stated timeline straight into CRM fields so scoping calls start with technical context already logged. |
Common penetration testing lead scenarios
Compliance-driven web app test
A prospect needs a web application tested to satisfy an auditor, has documented authorization, and wants to start immediately — the intake flags this as a high-priority, ready-to-schedule engagement.
Unauthorized network test request
Someone asks for a network infrastructure test but can't confirm they own or have written permission for the systems, triggering the low 'no' weight on the authorization question and holding the lead until proof is provided.
Large-scope cloud engagement
A first-time client with 21+ endpoints across a cloud environment selects 'within three months,' giving your team a sizable but not urgent lead to plan resourcing around.
Exploratory prospect, no timeline
A visitor marks the environment as 'not sure' and says they're just exploring options, which the intake still scores as viable but routes for a clarifying conversation rather than an immediate scoping call.
Connect Cliont to your workflow
Send leads
HubSpot, HighLevel, Salesforce, JobNimbus
Book projects
Google Calendar, Outlook Calendar, Calendly
Notify your team
Email, SMS, Slack
Automate follow-up
Zapier, Webhooks, API
Simple, transparent pricing
Choose the plan that works for your business.
Professional
Unlimited intake forms and leads for your growing business.
- Unlimited intake forms
- Custom video greetings
- AI-powered voice bot
- English + Spanish support
- Automatic lead scoring
- Digital estimates & e-signatures
- Photo, video & file upload
- Advanced analytics dashboard
Pay Per Lead
Only pay when you receive a qualified lead.
- Unlimited intake forms
- Custom video greetings
- AI-powered voice bot
- English + Spanish support
- Automatic lead scoring
- Digital estimates & e-signatures
- Photo, video & file upload
- Charged only for submitted leads
More cybersecurity intake templates
Penetration Testing lead-intake FAQs
How does the intake stop us from scoping a test we're not legally cleared to run?
The authorization question carries the heaviest weight in the catalog — a documented 'yes' scores 10, while 'no' scores 1 — so unauthorized requests are flagged well before your team invests time in a scoping call.
What if a lead says they're not sure what type of environment needs testing?
'Not sure' is still counted as a viable environment response in the scoring, but it signals that the scoping call should start with clarifying the target systems rather than jumping straight to logistics.
How does this intake differ from your Vulnerability Assessment intake?
This flow is built around active, authorized exploitation of specific systems, so it asks for documented authorization and in-scope counts up front — leads that only want automated scanning are a better fit for the Vulnerability Assessment intake.
Does the intake help us estimate engagement size before the call?
Yes — the question on how many systems, applications, or endpoints are in scope gives your team a rough sense of engagement size before you ever open the CRM record.
Can the intake tell us if this is a repeat client or a first-time test?
The prior-testing question captures whether the environment has ever undergone a penetration test before, which helps your team decide whether the call is a baseline assessment or a retest against prior findings.
Why does the intake ask what's driving the request?
Knowing whether the need stems from a compliance deadline, a recent incident, a partner request, or a routine assessment lets your team frame the scoping call and prioritize accordingly, even though the driver itself isn't weighted for scoring.
Turn penetration testing visitors into qualified clients
Give every penetration testing visitor a guided intake instead of a dead contact form — and get a scored, qualified lead before you take the first call.